Create an AWS KMS provider with the given options.
List all KMS keys, optionally filtered by usage or enabled state.
Optional_filters: { usage?: string; enabled?: boolean }Retrieve metadata for a specific KMS key by ID.
Create a new KMS key with the given algorithm and usage.
Optionalmetadata: Record<string, string>Enable a previously disabled KMS key.
Disable a KMS key so it cannot be used for operations.
Schedule a KMS key for deletion after a pending window.
Encrypt plaintext using a KMS key, with optional encryption context.
Optionalcontext: Record<string, string>Decrypt ciphertext using a KMS key, with optional encryption context.
Optionalcontext: Record<string, string>Sign data using a KMS signing key.
Verify a signature against data using a KMS signing key.
Enable automatic key rotation and return updated metadata.
AWS KMS adapter.
Wraps the
@aws-sdk/client-kmsSDK to provide the unified KmsProvider interface. Install@aws-sdk/client-kmsas a peer dependency.Example